Flinn.ai

Information Security Compliance Manager

Flinn.ai WorkFromHome

Stellenbeschreibung:

Overview

We’re looking for an Information Security Compliance Manager (ISO 27001 / GDPR / HIPAA) with 3-5 years of experience to take ownership of our certified ISO/IEC 27001 ISMS and our privacy program in a health-data SaaS environment. You will maintain and continuously improve our ISO 27001 system (supported by Vanta), lead internal and external (surveillance) audits, and evolve our GDPR setup to also cover HIPAA expectations and special categories of data in close partnership with Engineering and Tech.

Why Flinn?

  • We are building a truly exceptional culture: While many companies claim to have a great culture, we invite you to discover what truly sets ours apart. Visit our career page, speak with our team, listen to our founders’ podcast, or experience our culture first-hand during the interview process.
  • Make a Meaningful Impact: Your work at Flinn contributes directly to solutions that improve people’s health and lives by making high-quality health products accessible for everyone.
  • Experienced, well-funded, highly professional : As well-funded startup veterans, we know how to sustain long-term business health and success, ensuring an environment for continuous personal growth.

Your contributions to our journey:

  • Take over end-to-end ownership of our certified ISO 27001 ISMS , ensuring it stays effective, current, and audit-ready year-round
  • Lead preparation and execution support for surveillance audits , including evidence readiness, stakeholder preparation, and closing findings
  • Run the internal audit program and drive corrective actions (CAPA) to closure with clear ownership and measurable outcomes
  • Harmonize security and privacy governance by aligning ISO 27001 and GDPR processes (risk, vendor management, incident/breach handling, access governance, retention)
  • Expand the privacy program from GDPR to include HIPAA-related requirements and robust handling of health/sensitive data (incl. vendor/subprocessor controls)
  • Translate security/privacy requirements into pragmatic, actionable work for Engineering and Operations (“what needs to be done, how, and what evidence is needed”)
  • Improve scalability of compliance operations using Vanta (evidence automation, control monitoring, clean documentation) and help prepare for future SOC 2 / NIST needs

What you need to be successful:

  • 3–5 years of experience in information security compliance / ISMS / GRC in a tech or SaaS environment
  • Hands-on ownership of an ISO/IEC 27001 ISMS in a certified organization, including operating cadences (risk, SoA, control reviews, metrics, continual improvement)
  • Audit experience you can point to : participation/leadership in external audits (surveillance/recertification) and successful closure of findings
  • Ability to plan/execute (or coordinate) internal audits and drive corrective actions through to verified completion
  • Practical GDPR operations experience (e.g., RoPA, DPIAs, vendor/subprocessor governance, DSAR coordination, incident/breach support)
  • Comfort working in environments processing health data / special categories of data , and ability to operationalize privacy and security expectations (HIPAA exposure is a plus)
  • Solid technical foundation to collaborate with Engineering on controls and evidence (IAM/SSO/MFA/RBAC, logging/audit trails, vulnerability & patch mgmt, change mgmt, cloud/SaaS fundamentals)
  • Excellent English communication skills (written and verbal); German is a plus
  • Location: Vienna or Berlin (hybrid/onsite expectations as applicable)

Attributes we are looking for:

  • Pragmatic doer mindset: you turn standards into workable processes and evidence without creating unnecessary overhead
  • Structured and reliable: strong follow-through, clear prioritization, and comfort running recurring cadences (audits, reviews, actions)
  • Confident stakeholder manager: you can influence cross-functionally without formal authority and build trust with Engineering
  • Audit-ready thinking: you know what “good evidence” looks like and keep the program continuously ready, not just before audits
  • Clear communicator and translator: you can explain requirements simply and adapt your message to technical and non-technical audiences
  • Ownership mentality: you proactively identify gaps, propose improvements, and drive them to completion

NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    28 Jan 2026
  • Standort:

    WorkFromHome
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!

Diese Jobs passen zu Deiner Suche:

ista SE
Manager / Senior Specialist Information Security (m/w/d)
ista SE
partner ad:Stepstone partner
Vollzeit Essen
11 Dez 2025Development & IT
REWE digital
Information Security Manager (m/w/d)
REWE digital
partner ad:Stepstone partner
Vollzeit Köln
12 Dez 2025Development & IT
Aareal Bank AG
Security Manager Privileged Access - Planung & Steuerung / IT Compliance (w/m/d)
Aareal Bank AG
Vollzeit Wiesbaden
25 Jan 2026Development & IT
Information Security & Compliance Senior Specialist (f/m/d) for Global Sovereign Cloud Delivery
SAP SE
Vollzeit St. Leon-Rot
21 Jan 2026
Assistant Compliance & Information Security (m/w/d)
ZCC Cutting Tools Europe GmbH
Vollzeit WorkFromHome
21 Jan 2026
Western Union
Senior Manager, Information Security & Resilience Risk (ICT Risk) (m/w/d) - Western Union
Western Union
Vollzeit WorkFromHome
26 Jan 2026
Specialist - Information Security
Scope Ratings
Vollzeit Berlin
26 Jan 2026
IT Security Specialist – Compliance & Governance (m/w/d)
Bauer Mat
Vollzeit
26 Jan 2026